Look at what actually happened. Equifax was using the Struts framework. This is a very safe, popular choice. They were using what everybody else uses.
There was a critical vuln in the framework, and they failed to update their box for N months. But we're talking only a few months. N is very small -- maybe four? And yeah, you can argue that four months is an absurdly long time to have a known critical vuln in production. But I guarantee you that most people reading this work at companies that are similarly vulnerable. Attacks are simply rare.
Whatever company you work for, if you do not have regular pentests, you are no better off. And even if you do, it's overwhelmingly likely that you've overlooked some lonely outdated server that's still running on your network because Bob set it up a year ago and forgot about it and oh look now you have a pivot into your whole network.
It seems very strange to choose this one company and crucify them just because they lost your data. Everybody is insecure everywhere always, and we've learned to tolerate this by pretending it's not true or that it doesn't exist or that it's not a big deal. But you know what? It is true. That truth will continue to manifest itself in the years to come. No matter how much you'd like it not to be true, your stuff will still get stolen. Usually you just don't hear about it.
Yes, it was stupid for them to have everybody's PII attached to that one webserver. A single point of failure should never result in compromising the whole system. But think about how that architecture would work in practice. A customer service rep still needs to get at most of your data. It's a credit bureau. Where would the data be stored in a way that a remote code exec wouldn't be able to snag it?
Equifax's crime boils down to "they failed to run the equivalent of sudo apt-get upgrade on their framework." When you're managing a fleet of hundreds or thousands of machines, this is a situation that almost all of us have wound up in. If we can't get it right, why do you want the execs' heads to roll? Are you sure you won't be next on the chopping block?
Think about it this way: the time between "someone discovered a vuln in Spring" and "the attackers stole 150M credit reports" was just a few months. Are you sure Equifax wasn't a victim here? Someone threw a cinderblock through their window and made off with their trove of data.
Except of course, it wasn't a cinderblock through a window. It was completely silent. Even if your firewall is great, you can still smuggle data out of a network using DNS alone.
Food for thought.